Improper access control in 3rd Generation Intel Xeon Scalable Processors - CVE-2021-33117

 

Improper access control in 3rd Generation Intel Xeon Scalable Processors - CVE-2021-33117

Published: May 17, 2022


Vulnerability identifier: #VU63349
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33117
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions and gain access to sensitive information.


Affected software

3rd Generation Intel Xeon Scalable Processors
Dell PowerEdge BIOS 15G
Dell PowerEdge BIOS 14G
Amazon Linux AMI
F5OS
Ubuntu
microcode_ctl
intel-microcode (Ubuntu package)
Dell PowerEdge BIOS 13G
VxFlex ESXi
Integrated System for Microsoft Azure Stack Hub

How to mitigate CVE-2021-33117

Install updates from vendor's website.

Dell PowerEdge BIOS 15G - update to 1.6.5
microcode_ctl - update to 2.1-53
Dell PowerEdge BIOS 14G - update to 2.14.2
Dell PowerEdge BIOS 13G - update to 2.15.0
intel-microcode (Ubuntu package) - addressed in versions 3.20220510.0ubuntu0.16.04.1+esm1, 3.20220510.0ubuntu0.18.04.1, 3.20220510.0ubuntu0.20.04.1, 3.20220510.0ubuntu0.21.10.1, 3.20220510.0ubuntu0.22.04.1
VxFlex ESXi - update to 6.7 P07
Integrated System for Microsoft Azure Stack Hub - update to 2210

External References

Related Security Bulletins